Document: draft-ietf-spring-srv6-security Title: Segment Routing IPv6 Security Considerations Reviewer: Henning Rogge Review result: Has Nits
Hello, I was asked to do a review of draft-ietf-spring-srv6-security-16 by the rtg-dir. At first, I really like the extended Terminology section of this draft, this makes the document more precise which is especially important for security documents. Section 4 Nit: I am not sure MACsec needs to be discussed here, its a fully authenticaed and encrypted layer-2 connection as far as I know... which would mean an attacker without the key cannot even read the IP bytestream. If MACsec is used to secure the trusted domain it needs to be done for all layer-2 links in the domain, including the one to/from/between routers that do not process the SRH. Nothing special in regards to SR. General Nit: RFC 8986 already states that using IPv6 Authentication Headers (AH) is not applicable for SR deployments. Should this document mention any kind of interaction with Encapsulating Security Payload (ESP) header? Or are there just no interactions or are they out of scope of this document? I think the document does a good job discussing the security aspects of Segment Routing. I don't follow the Spring WG mailing list, so if these two nits have already be discussed I would consider the document Ready. Henning Rogge Fraunhofer FKIE - Germany _______________________________________________ spring mailing list -- [email protected] To unsubscribe send an email to [email protected]
